Vulnerability Description
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed Crypto | <= 3.1.0 |
| Arm | Mbed Tls | >= 2.1.8, < 2.28.8 |
| Fedoraproject | Fedora | 38 |
Related Weaknesses (CWE)
References
- https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-sVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/Vendor Advisory
- https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-sVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/Vendor Advisory
FAQ
What is CVE-2024-28960?
CVE-2024-28960 is a vulnerability with a CVSS score of 8.2 (HIGH). An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
How severe is CVE-2024-28960?
CVE-2024-28960 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28960?
Check the references section above for vendor advisories and patch information. Affected products include: Arm Mbed Crypto, Arm Mbed Tls, Fedoraproject Fedora.